Vulnerabilities (CVE)

Filtered by vendor Tenda Subscribe
Total 1846 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-39784 1 Tenda 2 Ac8 Firmware, Ac8v4 2026-07-09 N/A 7.5 HIGH
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the save_virtualser_data function.
CVE-2023-33530 1 Tenda 2 G103, G103 Firmware 2026-07-09 N/A 8.8 HIGH
There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges.
CVE-2022-35201 1 Tenda 2 Ac18, Ac18 Firmware 2026-07-09 N/A 9.8 CRITICAL
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
CVE-2022-30023 1 Tenda 2 Hg9, Hg9 Firmware 2026-07-09 9.0 HIGH 8.8 HIGH
Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
CVE-2021-44971 1 Tenda 4 Ac15, Ac15 Firmware, Ac5 and 1 more 2026-07-09 7.5 HIGH 9.8 CRITICAL
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.
CVE-2025-46035 1 Tenda 2 Ac6, Ac6 Firmware 2026-07-05 N/A 7.5 HIGH
Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in an unauthenticated HTTP GET request to the /goform/openSchedWifi endpoint
CVE-2025-61498 1 Tenda 2 Ac8, Ac8 Firmware 2026-07-05 N/A 7.5 HIGH
A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted packet.
CVE-2025-57573 1 Tenda 2 F3, F3 Firmware 2026-07-05 N/A 5.6 MEDIUM
Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the wifiTimeClose parameter in goform/setWifi.
CVE-2025-57572 1 Tenda 2 F3, F3 Firmware 2026-07-05 N/A 5.6 MEDIUM
Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentControl.
CVE-2025-57571 1 Tenda 2 F3, F3 Firmware 2026-07-05 N/A 5.6 MEDIUM
Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow. via the macFilterList parameter in goform/setNAT.
CVE-2025-57570 1 Tenda 2 F3, F3 Firmware 2026-07-05 N/A 5.6 MEDIUM
Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the QosList parameter in goform/setQoS.
CVE-2025-57569 1 Tenda 2 F3, F3 Firmware 2026-07-05 N/A 5.6 MEDIUM
Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the portList parameter in /goform/setNAT.
CVE-2025-55564 1 Tenda 2 Ac15, Ac15 Firmware 2026-07-05 N/A 7.5 HIGH
Tenda AC15 v15.03.05.19_multi_TD01 has a stack overflow via the list parameter in the fromSetIpMacBind function.
CVE-2025-51089 1 Tenda 2 Ac8, Ac8 Firmware 2026-07-05 N/A 6.5 MEDIUM
Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow.
CVE-2025-51088 1 Tenda 2 Ac8, Ac8 Firmware 2026-07-05 N/A 5.3 MEDIUM
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/WifiGuestSet. The manipulation of the argument `shareSpeed` leads to stack-based buffer overflow.
CVE-2025-51087 1 Tenda 2 Ac8, Ac8 Firmware 2026-07-05 N/A 8.6 HIGH
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow.
CVE-2025-51085 1 Tenda 2 Ac8, Ac8 Firmware 2026-07-05 N/A 5.3 MEDIUM
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the argument `timeZone` and `timeType` leads to stack-based buffer overflow.
CVE-2025-51082 1 Tenda 2 Ac8, Ac8 Firmware 2026-07-05 N/A 5.3 MEDIUM
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZone` leads to stack-based buffer overflow.
CVE-2025-45343 1 Tenda 2 W18e, W18e Firmware 2026-07-05 N/A 9.8 CRITICAL
An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module in the goform/setmodules route.
CVE-2025-29217 1 Tenda 2 W18e, W18e Firmware 2026-07-05 N/A 6.5 MEDIUM
Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.